Tüm alıştırma soruları

2232 soru

Soru 1701Soru

An organization relies on a legacy payment processing gateway that cannot be immediately upgraded due to vendor dependencies. A recent assessment identified multiple unpatched vulnerabilities in the gateway. To manage the associated exposure, the security team implements microsegmentation and deploys an inline web application firewall (WAF) to block exploit attempts, while the executive leadership team purchases a comprehensive cyber liability insurance policy to cover potential financial losses. Which of the following risk response strategies are implemented in this scenario? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Risk mitigation; Risk transference

Cevap

The organization demonstrates risk mitigation by deploying technical security controls (microsegmentation and WAF) and risk transference by purchasing cyber liability insurance.
Risk mitigation is illustrated by deploying technical controls (microsegmentation and a web application firewall) to minimize vulnerability exposure. Risk transference is illustrated by securing a cyber liability insurance policy to pass monetary risk to an insurer.

Adım Adım Çözüm

1
Analyze the technical security safeguards deployed by the security team.
Microsegmentation and inline web application firewalls lower the likelihood and impact of attacks against the legacy system, which represents risk mitigation.
Risk mitigation reduces risk exposure to an acceptable level using technical, administrative, or physical controls.
2
Analyze the financial protection measures authorized by executive leadership.
Purchasing cyber liability insurance shifts the monetary burden of potential breach incidents to the insurance carrier, which represents risk transference.
Risk transference reallocates financial risk exposure to a third party.

Anahtar Kavram

Risk Response Strategies
Soru 1702Soru

A financial analyst receives an unexpected telephone call from an individual claiming to be a senior analyst from the corporate internal audit department. The caller states that an urgent financial discrepancy was flagged during an ongoing audit and directs the analyst to verbally confirm their network login credentials and multi-factor authentication code to verify their identity before the system is locked out. Which social engineering attack vector is demonstrated in this scenario?

Cevabı ve açıklamayı göster

Cevap: Vishing

Cevap

The correct attack vector is vishing.
The correct option is vishing because the social engineering attempt was carried out using a direct voice telephone call to manipulate the victim into revealing sensitive login credentials and multi-factor authentication tokens.

Adım Adım Çözüm

1
Analyze the communication medium described in the incident scenario.
The attack occurs via a direct telephone call (voice communication).
Identifying the transmission channel differentiates voice-based social engineering from email or text messaging.
2
Evaluate the attacker's tactic and objective.
The caller uses pretexting (impersonating an internal auditor) to create urgency and trick the victim into sharing sensitive authentication factors.
Social engineering attacks often leverage trust and urgency to bypass standard security procedures.
3
Map the medium and tactic to standard security taxonomy terminology.
Voice-based phishing conducted over the telephone is defined as vishing (voice phishing).
CompTIA Security+ distinguishes social engineering variants based on delivery mechanisms and target profiles.

Anahtar Kavram

Vishing (Voice Phishing)
Tahmini Süre:1m 0s
Soru 1703Soru

A United States-based mortgage technology provider processes personal financial records and loan applications for regional banks. The organization plans to migrate its infrastructure to a multi-tenant public cloud model while maintaining remote administration capabilities for offshore engineering teams. During a compliance evaluation, the Chief Information Security Officer (CISO) must ensure alignment with the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule regarding administrative and technical data protections. Which of the following strategies best fulfills the legal compliance requirements for safeguarding consumer financial data in this architecture?

Cevabı ve açıklamayı göster

Cevap: Mandate multi-factor authentication for all personnel accessing customer financial systems, enforce data encryption in transit and at rest, and designate a qualified individual to oversee the information security program.

Cevap

Mandate multi-factor authentication for all personnel accessing customer financial systems, enforce data encryption in transit and at rest, and designate a qualified individual to oversee the information security program.
The correct option directly implements the explicit requirements outlined in the FTC GLBA Safeguards Rule. Under GLBA, financial entities and their service providers must protect consumer non-public personal information by implementing technical safeguards—such as multi-factor authentication and data encryption both at rest and in transit—and administrative safeguards, such as designating a qualified individual to manage and oversee the security program.

Adım Adım Çözüm

1
Identify the primary governing regulation and its scope.
The target organization handles non-public personal financial information for banking customers, bringing it directly under the jurisdiction of the FTC Gramm-Leach-Bliley Act (GLBA) Safeguards Rule.
Regulatory compliance mandates depend on aligning technical controls directly with the statutory obligations of the specific governing framework.
2
Analyze the mandatory administrative and technical safeguards required under the GLBA Safeguards Rule updates.
The rule mandates specific baseline controls: robust access controls including multi-factor authentication (MFA) for accessing customer data, encryption of data at rest and in transit, continuous monitoring or vulnerability testing, and administrative oversight by a designated qualified individual.
Financial privacy regulations mandate both administrative accountability and rigorous technical controls to protect non-public personal information.
3
Evaluate the proposed operational options against these regulatory requirements.
Enforcing MFA, implementing end-to-end encryption for storage and transit in the cloud environment, and appointing a qualified individual directly fulfills the statutory requirements of the GLBA Safeguards Rule.
This combination addresses both technical protection measures for multi-tenant/offshore access and formal governance oversight required by law.

Anahtar Kavram

Gramm-Leach-Bliley Act (GLBA) Safeguards Rule Requirements
Tahmini Süre:2m 0s
Soru 1704Soru

An enterprise risk manager is formalizing the organization's Business Continuity Management (BCM) testing program to validate recovery assumptions established during the Business Impact Analysis (BIA). Match each business continuity exercise type on the left to its corresponding operational execution methodology on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Tabletop Exercise
Structured Walk-Through Test
Parallel Test
Full-Interruption Test

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Tabletop Exercise matches verbal scenario discussion among key stakeholders. Structured Walk-Through Test matches line-by-line review of continuity documentation. Parallel Test matches concurrent processing on backup systems without disrupting production. Full-Interruption Test matches completely shutting down primary systems to migrate live operations.
Each business continuity exercise type corresponds to a specific level of operational disruption and validation depth. Tabletop exercises involve verbal scenario discussions. Structured walk-through tests involve detailed documentation audits. Parallel tests run recovery systems concurrently alongside live production without risk of downtime. Full-interruption tests intentionally shut down primary systems to validate complete operational failover.

Adım Adım Çözüm

1
Analyze discussion-based exercise methods
Identify that Tabletop Exercises focus on verbal scenario walkthroughs without hardware deployment.
Tabletop exercises test decision-making and awareness in a meeting setting.
2
Differentiate documentation validation from scenario discussion
Identify that Structured Walk-Through Tests focus on step-by-step reading and verification of the written plan.
Structured walk-throughs ensure that the disaster recovery documentation itself is complete and accurate.
3
Evaluate operational recovery testing methodologies
Match Parallel Testing with concurrent redundant system processing that maintains active production, and Full-Interruption Testing with disabling live systems to force failover.
Parallel tests minimize business risk while testing hardware readiness, whereas full-interruption tests validate real-time failover under actual outage conditions.

Anahtar Kavram

Business Continuity Plan (BCP) Testing and Exercise Methodologies
Soru 1705Soru

Match each audit or attestation report type to its primary operational purpose.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

SOC 1 Report
SOC 2 Type I Report
SOC 2 Type II Report
SOC 3 Report

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

SOC 1 matches financial reporting controls; SOC 2 Type I matches point-in-time control design evaluation; SOC 2 Type II matches control design and operational effectiveness over a period of time; SOC 3 matches high-level public summaries.
Each attestation serves a distinct audit purpose: SOC 1 evaluates financial reporting controls; SOC 2 Type I assesses control design at a single snapshot date; SOC 2 Type II verifies control design and operational performance over a specified evaluation period; and SOC 3 provides a publicly distributable summary.

Adım Adım Çözüm

1
Differentiate financial assurance reports from trust services security reports.
SOC 1 addresses financial reporting (ICFR), whereas SOC 2 and SOC 3 address security, availability, and confidentiality.
Organizations use SOC 1 when third-party services directly impact financial statements.
2
Distinguish between Type I and Type II report timeframes and depth.
Type I is a snapshot evaluation of control design at a single point in time, while Type II measures operational performance over a multi-month period.
Type II requires extensive historical log review and evidence gathering to prove controls operated as designed over time.
3
Identify the report designed for public distribution.
SOC 3 provides a generalized public summary.
Unlike SOC 2 reports, which contain sensitive architectural details, SOC 3 reports are stripped of confidential data so they can be shared freely.

Anahtar Kavram

SOC Report Types and Attestation Scopes
Soru 1706Soru

A cloud service provider needs to publish a high-level attestation document on its public website to demonstrate compliance with security best practices to prospective clients, without disclosing detailed control design or confidential testing procedures. Which report fulfills this requirement?

Cevabı ve açıklamayı göster

Cevap: SOC 3 report

Cevap

A SOC 3 report provides a general-use, publicly shareable summary of security attestations without exposing confidential system design details.
A SOC 3 report is specifically created for general public distribution. It provides an executive summary of an organization's compliance with Trust Services Criteria without revealing sensitive details regarding system architecture or specific control testing results.

Adım Adım Çözüm

1
Identify the primary requirement in the scenario.
The organization requires a publicly accessible security attestation report that excludes sensitive internal architectural and testing details.
Prospective customers need proof of security posture, but public distribution of detailed audit reports poses a security risk.
2
Evaluate the scope and audience of available SOC reports.
SOC 1 and SOC 2 reports are restricted-use documents intended for management and existing clients, whereas SOC 3 reports are designated for public distribution.
SOC 3 provides an executive summary based on SOC 2 Trust Services Criteria without disclosing proprietary system details.

Anahtar Kavram

SOC 3 Public Attestation Reports
Soru 1707Soru

A municipal transit authority is establishing a comprehensive security governance structure to ensure regulatory compliance across all operational departments. The security team must distinguish between mandatory governance directives and discretionary recommendations. Which of the following governance components represent mandatory requirements within an enterprise security governance framework? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Security Policies defining executive direction and high-level organizational mandates; Security Standards specifying explicit mandatory operational metrics and technical baseline rules

Cevap

Security Policies defining executive direction and high-level organizational mandates, and Security Standards specifying explicit mandatory operational metrics and technical baseline rules.
Security policies and security standards are mandatory elements within a security governance framework. Executive management establishes policies to define overarching compliance mandates, while security standards specify obligatory technical requirements and operational baselines required to enforce those policies.

Adım Adım Çözüm

1
Analyze governance framework document tiers
Identify that enterprise governance structures categorize documents into compulsory directives and discretionary recommendations.
Governance frameworks establish clear boundaries between obligatory compliance controls and suggested guidance.
2
Evaluate compulsory governance mechanisms
Policies establish top-level executive directives, while standards define specific technical baseline specifications and mandatory operational rules.
Both policies and standards carry mandatory compliance authority within an organization.
3
Differentiate from discretionary items and technical implementation artifacts
Guidelines are non-binding recommendations, control categories are functional classifications, and access matrices are technical authorization artifacts.
Only policies and standards function as mandatory governance framework elements.

Anahtar Kavram

Enterprise Security Governance Hierarchy and Mandatory vs. Discretionary Framework Components
Soru 1708Soru

Match each security audit, assessment, or attestation deliverable with its primary operational purpose and evaluation scope.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

SOC 2 Type I Report
SOC 2 Type II Report
SOC 3 Report
ISO/IEC 27001 Certification

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

SOC 2 Type I matches point-in-time design suitability; SOC 2 Type II matches design suitability and operating effectiveness over a defined period; SOC 3 matches public-facing executive summary attestation; ISO/IEC 27001 matches accredited ISMS framework certification.
Each deliverable maps strictly to its evaluation scope: SOC 2 Type I assesses control design at a single point in time; SOC 2 Type II assesses design and operating effectiveness over a monitoring period; SOC 3 is a freely distributable public summary; ISO/IEC 27001 certifies the overall Information Security Management System against international standard criteria.

Adım Adım Çözüm

1
Analyze the timeframe requirement of SOC 2 attestation reports
Distinguish Type I (point in time, design suitability only) from Type II (over a testing period, design and operating effectiveness).
Type I audits examine control architecture at a specific date snapshot, whereas Type II requires historical evidence of operating consistency.
2
Determine the intended distribution audience for SOC reports
Identify SOC 3 as the publicly distributable version of SOC 2.
SOC 2 reports contain sensitive system descriptions for restricted use, while SOC 3 reports provide high-level assurance for prospective customers and public distribution.
3
Identify international framework certifications
Match ISO/IEC 27001 to the formal accredited audit of an Information Security Management System (ISMS).
ISO 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an organizational ISMS.

Anahtar Kavram

Third-Party Security Audits, Attestations, and Framework Certifications
Soru 1709Soru

Match each regulatory framework or standard to its primary governance scope and legal mandate.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

FISMA
GDPR
PCI DSS
SOX

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

FISMA matches the security mandate for U.S. federal government agencies; GDPR matches personal privacy rights for EU individuals; PCI DSS matches contractual requirements for credit card processing merchants; SOX matches internal financial reporting controls for public companies.
Each regulation or standard aligns directly with its designated scope: FISMA governs U.S. federal agency systems; GDPR governs European consumer data privacy; PCI DSS governs payment card merchant data environments; and SOX governs internal financial reporting controls for public companies.

Adım Adım Çözüm

1
Identify the mandate governing federal information systems.
FISMA establishes information security practices for U.S. federal agencies and their supporting contractors.
Understanding federal scope separates public-sector statutory frameworks from private commercial standards.
2
Determine the regulation protecting European personal privacy rights.
GDPR regulates personal data processing, consumer consent, and international data transfers for EU residents.
GDPR focuses on data subject privacy rights across international boundaries.
3
Identify the standard governing payment card environments.
PCI DSS is a non-governmental contractual standard required by payment brands for entities handling credit card transactions.
Cardholder data environments are regulated by industry contractual standards rather than federal legislation.
4
Determine the legal requirement for public corporate financial transparency.
SOX mandates internal accounting safeguards and audit trails for publicly traded corporate financial disclosures.
SOX targets corporate governance and accounting oversight to protect investors.

Anahtar Kavram

Regulatory Compliance Frameworks and Governance Scopes
Soru 1710Soru

An enterprise application runs in a cloud environment using containerized microservices operating under an immutable infrastructure deployment model. A vulnerability scan detects a critical remote code execution vulnerability within a software library contained inside several active production containers. Which of the following patch and configuration management practices should the security team perform to resolve the vulnerability?

Cevabı ve açıklamayı göster

Cevap: Update the base container image with the patched library, validate the build in a testing pipeline, and redeploy new container instances to replace the vulnerable ones.

Cevap

Update the base container image with the patched library, validate the build in a testing pipeline, and redeploy new container instances to replace the vulnerable ones.
In an immutable infrastructure deployment model, running components (such as containers or virtual machine instances) are never patched or modified directly in production. When a security update or patch is required, the baseline source image (e.g., container image specification) is updated with the new library version, validated in a staging or CI/CD environment, and then used to deploy fresh instances while decommissioning the old, vulnerable ones. This eliminates configuration drift and ensures consistency across environments.

Adım Adım Çözüm

1
Identify the core deployment architecture model.
The infrastructure is designated as immutable, meaning running instances are never modified in place.
Configuration changes and updates in immutable environments must follow a build-test-deploy lifecycle via images.
2
Select the appropriate patch management workflow for containerized images.
Modify the base container image file (e.g., Dockerfile) to reference the patched dependency version.
This guarantees that all future deployments inherit the correct security posture consistently.
3
Test and swap running instances.
Pass the updated image through automated staging tests and terminate vulnerable production containers while deploying new instances.
Ensures zero configuration drift and remediates the vulnerability cleanly.

Anahtar Kavram

Immutable Infrastructure Patching
Tahmini Süre:1m 15s
Soru 1711Soru

A multinational fintech enterprise headquartered in Canada hosts its core payment processing and accounting platform in an IaaS cloud environment. The platform processes customer credit card transactions while also storing records subject to Sarbanes-Oxley (SOX) compliance for financial reporting integrity. Which of the following compliance actions and technical security controls must the organization enforce to satisfy these legal and regulatory frameworks? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Implement strict access control policies, segregation of duties, and immutable logging for database systems housing financial statements.; Isolate the Cardholder Data Environment (CDE) through network segmentation and enforce strong encryption on stored primary account numbers.

Cevap

The organization must implement strict access control policies, segregation of duties, and immutable logging for financial reporting systems (SOX requirement), and isolate the Cardholder Data Environment (CDE) while encrypting stored account numbers (PCI-DSS requirement).
Establishing strict access control policies, segregation of duties, and audit logging for financial databases directly satisfies SOX Section 404 mandates regarding internal control over financial reporting. Simultaneously, isolating the Cardholder Data Environment (CDE) and encrypting primary account numbers directly aligns with PCI-DSS requirements for protecting payment data.

Adım Adım Çözüm

1
Analyze regulatory scope requirements for Sarbanes-Oxley (SOX) Act compliance.
Identify that SOX focuses on internal financial reporting controls, access tracking, data integrity, and auditing of financial systems.
SOX Section 404 requires verifiable internal controls over financial disclosures.
2
Analyze regulatory scope requirements for Payment Card Industry Data Security Standard (PCI-DSS).
Identify that processing credit card data mandates Cardholder Data Environment (CDE) scope reduction via segmentation and encryption of primary account numbers (PAN).
PCI-DSS enforces specific technical controls to reduce card fraud and scope exposure.
3
Evaluate distractors against cloud responsibility models and security control types.
Disqualify offloading compliance liability to an IaaS provider and using network firewalls to fix code bugs.
Data governance remains with the tenant in IaaS, and network firewalls do not solve application software code flaws.

Anahtar Kavram

Regulatory Compliance Alignment and Mandatory Control Verification
Soru 1712Soru

An organization is enhancing its third-party governance framework to address vendor oversight and supply chain security. Match each third-party risk management instrument on the left with its primary operational purpose on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Vendor Security Assessment Questionnaire (VSAQ)
Right-to-Audit Contractual Clause
Hardware Bill of Materials (HBOM)
Service Level Agreement (SLA)

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Vendor Security Assessment Questionnaire matches with evaluating self-reported security controls; Right-to-Audit Clause matches with establishing legal authority to inspect controls; Hardware Bill of Materials matches with tracking physical component sourcing and sub-tier provenance; Service Level Agreement matches with defining measurable service performance metrics.
Each instrument fulfills a specific role in third-party risk management: Questionnaires assess self-reported baseline posture during onboarding, Right-to-Audit provisions grant verification permissions, HBOMs track physical component provenance against tampering, and SLAs define operational metrics and breach remedies.

Adım Adım Çözüm

1
Identify the primary purpose of pre-onboarding questionnaires.
Match Vendor Security Assessment Questionnaire (VSAQ) with evaluating self-reported security controls during initial onboarding.
VSAQs are standardized tools used during initial risk assessment to gauge vendor compliance and risk profile.
2
Analyze contractual inspection rights.
Match Right-to-Audit Contractual Clause with establishing legal authority to inspect physical and technical controls.
Right-to-audit clauses ensure the client is legally permitted to independently audit or inspect vendor facilities and systems.
3
Evaluate hardware supply chain oversight mechanisms.
Match Hardware Bill of Materials (HBOM) with tracking component sourcing and sub-tier provenance.
An HBOM details all physical sub-components and integrated circuits, ensuring component origin integrity.
4
Determine performance operational contract mechanisms.
Match Service Level Agreement (SLA) with defining measurable service performance metrics and uptime expectations.
SLAs govern operational expectations, availability metrics, and remediation terms.

Anahtar Kavram

Third-Party Risk Management and Supply Chain Oversight Instruments
Soru 1713Soru

An enterprise Security Operations Center (SOC) analyst is reviewing network security monitoring alerts and NetFlow records for an internal workstation. The monitoring tools report suspicious outbound protocol activity originating from the host. Which of the following network security monitoring findings specifically indicate that DNS tunneling is being utilized for data exfiltration? (Select TWO).

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: A high volume of DNS TXT record queries containing high-entropy, encoded strings directed to an external authoritative name server; A significant increase in outbound payload data volume transmitted over UDP port 53 compared to established network baselines

Cevap

The network monitoring findings that indicate DNS tunneling for data exfiltration are a high volume of DNS TXT record queries containing high-entropy encoded strings directed to an external authoritative name server, and a significant increase in outbound payload data volume transmitted over UDP port 53 compared to established network baselines.
DNS tunneling abuses standard domain name resolution traffic to exfiltrate sensitive data or maintain covert communications. Network security monitoring tools identify this technique by detecting abnormally large outbound payload transfers on UDP port 53 and uncovering repeated DNS TXT requests containing long, high-entropy encoded subdomains destined for untrusted external name servers.

Adım Adım Çözüm

1
Analyze network protocol traffic volume against baseline metrics.
Identify anomalous outbound byte counts originating on UDP port 53.
Standard DNS queries are small in size; a large outbound byte transfer over port 53 indicates data payload encapsulation.
2
Inspect packet payloads and query record types within DNS monitoring logs.
Detect encoded high-entropy subdomain strings in TXT queries sent to external name servers.
Attackers structure exfiltrated data into subdomains resolved by attacker-controlled authoritative name servers to bypass standard egress filtering.

Anahtar Kavram

Detecting DNS tunneling and data exfiltration indicators using network security monitoring analysis
Soru 1714Soru

A hospital system contracts with a cloud-based Electronic Health Records (EHR) vendor. During a risk assessment, the security team discovers that the EHR vendor delegates its database backup and data archiving operations to an external sub-processor. Which of the following risk management controls best ensures that third-party and fourth-party security standards are maintained throughout this supply chain?

Cevabı ve açıklamayı göster

Cevap: Enforce contractual requirements that compel the primary vendor to flow down security controls and grant right-to-audit permissions for sub-processors

Cevap

Enforce contractual requirements that compel the primary vendor to flow down security controls and grant right-to-audit permissions for sub-processors.
Contractual flow-down clauses ensure that the primary vendor binds any sub-processors (fourth parties) to the same security standards and audit obligations agreed upon with the customer. This ensures end-to-end supply chain visibility and accountability.

Adım Adım Çözüm

1
Identify the risk vector in the supply chain scenario
Recognize that data handling extends beyond the primary third-party vendor to a fourth-party sub-processor.
Security risks propagate along the supply chain whenever a primary vendor delegates critical data functions to downstream service providers.
2
Evaluate the appropriate governance mechanism for fourth-party risk management
Determine that contractual flow-down obligations and right-to-audit provisions extend governance to sub-processors.
Direct contractual relationship exists only with the primary vendor; thus, contractual terms must obligate the primary vendor to enforce equivalent controls downstream.

Anahtar Kavram

Fourth-Party Risk Management and Flow-Down Contractual Provisions
Soru 1715Soru

Match each enterprise security incident scenario on the left with the specific social engineering attack vector utilized on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

An attacker registers a domain name containing a common misspelling of a corporate web portal to harvest employee authentication credentials.
An attacker leaves malware-infected USB flash drives scattered in the employee parking lot hoping someone inserts one into a company workstation.
An attacker contacts a shipping department while impersonating a logistics dispatcher to trick staff into redirecting a valuable shipment to an offsite address.
An attacker submits a fraudulent payment request to the accounts payable department designed to mimic a routine bill from an established third-party vendor.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

The credential harvesting site using a misspelled domain matches Typosquatting; the malware-laden flash drives left in the parking lot match Baiting; the fraudulent redirection of a shipment matches Diversion theft; and the fake vendor payment request matches Invoice fraud.
Each attack vector is correctly paired based on its primary delivery mechanism: Typosquatting uses deceptive URLs based on spelling errors; Baiting relies on physical media traps; Diversion theft manipulates physical delivery routes; and Invoice fraud uses deceptive billing requests to siphon corporate funds.

Adım Adım Çözüm

1
Analyze the web portal scenario involving misspelled domain registration.
Identify that exploiting typos in URLs to host spoofed credential-harvesting sites is typosquatting.
Typosquatting relies on user typographical mistakes when typing web addresses.
2
Analyze the physical media scenario involving unattended USB drives.
Identify that leaving physical media to entice curiosity is baiting.
Baiting relies on offering a physical item or incentive that promises a reward or satisfies curiosity.
3
Analyze the logistics scenario involving redirected shipments.
Identify that intercepting or altering courier deliveries is diversion theft.
Diversion theft specifically targets the supply chain or delivery process to steal physical goods.
4
Analyze the financial payment request scenario.
Identify that spoofing vendor billing documents to manipulate accounts payable is invoice fraud.
Invoice fraud uses pretexting and spoofed documentation to trick accounting into unauthorized disbursements.

Anahtar Kavram

Social Engineering Attack Vectors
Soru 1716Soru

An international aerospace technology firm headquartered in Munich, Germany, with active defense and commercial operations in the United States, discovers an unencrypted database snapshot exposed on a public cloud bucket. Investigation reveals that the exposed data contains both European Union customer Personal Identifiable Information (PII) and restricted US defense technical specifications subject to International Traffic in Arms Regulations (ITAR). Which action correctly fulfills the enterprise's concurrent statutory compliance and regulatory reporting duties?

Cevabı ve açıklamayı göster

Cevap: Report the personal data exposure to the relevant EU supervisory authority within 72 hours under GDPR while executing export control risk assessment and disclosure procedures with the US Department of State Directorate of Defense Trade Controls (DDTC).

Cevap

The enterprise must report the PII exposure to the designated EU supervisory authority within 72 hours under GDPR and follow statutory disclosure protocols with the US Directorate of Defense Trade Controls (DDTC) regarding ITAR technical data exposure.
The correct response recognizes that multinational operations dealing with dual-use or multi-jurisdictional data must satisfy independent statutory requirements simultaneously. Under GDPR, personal data breaches must be reported to the supervisory authority within 72 hours. Concurrently, public exposure of ITAR-controlled defense technical data constitutes an unauthorized export under US law, mandating formal disclosure procedures with the Directorate of Defense Trade Controls (DDTC).

Adım Adım Çözüm

1
Analyze the affected data classifications present in the incident
Identified European Union customer PII (governed by GDPR) and US export-controlled defense technical data (governed by ITAR).
Regulatory scope and notification bodies depend directly on data jurisdiction and legal governance classification.
2
Evaluate statutory GDPR compliance mandates
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach unless the breach is unlikely to result in a risk to individuals.
Unencrypted PII publicly exposed on the internet poses clear privacy risks to data subjects.
3
Evaluate statutory ITAR export compliance mandates
Unauthorized foreign or public access to ITAR technical data constitutes an illegal export, requiring voluntary or mandatory disclosure to the US Department of State DDTC.
Export control laws enforce strict statutory notification rules regardless of whether data exposure occurred via cloud misconfiguration.

Anahtar Kavram

Multi-Jurisdictional Regulatory Compliance & Breach Notification Mandates
Soru 1717Soru

A security analyst is reviewing internal security mechanisms to ensure they are properly classified according to CompTIA Security+ control categories. Which of the following mechanisms are classified as technical security controls? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Configuring a Host-based Intrusion Prevention System (HIPS) agent to block malicious memory execution attempts.; Enforcing 802.1X Network Access Control (NAC) on network switches to dynamically authenticate connecting devices.

Cevap

Configuring a Host-based Intrusion Prevention System (HIPS) agent and Enforcing 802.1X Network Access Control (NAC) are both technical security controls.
Technical controls (also known as logical controls) consist of software, hardware, firmware, or network protocol mechanisms implemented to safeguard systems and data. Configuring a Host-based Intrusion Prevention System (HIPS) to block malicious process execution and enforcing 802.1X Network Access Control (NAC) to dynamically validate connection attempts both rely directly on automated software logic and network technology to enforce access rules.

Adım Adım Çözüm

1
Define technical control category characteristics according to security frameworks.
Technical (logical) controls are safeguards executed through computer hardware, software, firmware, or network protocols.
Control categorization depends on the execution mechanism used to enforce security.
2
Evaluate each option against the technical control definition.
HIPS software and 802.1X network authentication operate automatically via system software and network devices (technical). Biometric door locks guard physical entry (physical), while facility security walk-through audits are procedural tasks performed by personnel (operational).
Distinguishing between technology-enforced, physical facility-enforced, and human-procedural controls yields the correct technical safeguards.

Anahtar Kavram

Security Control Categories (Technical, Operational, Physical, Managerial)
Tahmini Süre:1m 15s
Soru 1718Soru

A security administrator is evaluating enterprise cryptographic standards across various system modules. Match each cryptographic algorithm or mechanism on the left with its primary operational security application on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

PBKDF2 (Password-Based Key Derivation Function 2)
ECDHE (Elliptic Curve Diffie-Hellman Ephemeral)
HMAC-SHA256
AES-CBC with PKCS#7 Padding

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

PBKDF2 matches with mitigating offline brute-force attacks via key stretching. ECDHE matches with providing perfect forward secrecy during key exchange. HMAC-SHA256 matches with verifying data integrity and authenticity via a shared key. AES-CBC with PKCS#7 matches with bulk symmetric confidentiality for block payloads.
Each cryptographic mechanism is accurately matched to its intended operational function based on core security engineering principles: PBKDF2 hardens password authentication via key stretching; ECDHE provides ephemeral session key establishment with forward secrecy; HMAC-SHA256 delivers keyed integrity and authentication; and AES-CBC provides bulk block cipher confidentiality.

Adım Adım Çözüm

1
Analyze PBKDF2 function
Identified key stretching mechanism designed specifically to harden password hashes against brute-force attacks.
PBKDF2 applies salting and high iteration counts to increase computational cost per cracking attempt.
2
Analyze ECDHE mechanism
Identified ephemeral asymmetric key exchange algorithm providing perfect forward secrecy.
Ephemeral key generation guarantees that session keys are temporary and independent.
3
Analyze HMAC-SHA256 function
Identified keyed-hash message authentication code.
Combining a symmetric key with SHA-256 guarantees both integrity and message origin verification.
4
Analyze AES-CBC with PKCS#7 padding
Identified symmetric block cipher operating mode with padding.
AES-CBC encrypts 128-bit block units sequentially, requiring padding to fill incomplete final blocks.

Anahtar Kavram

Operational application of cryptographic primitives and key management mechanisms
Soru 1719Soru

An enterprise security risk manager is leading a Business Impact Analysis (BIA) for a newly integrated real-time interbank transaction settlement platform. To configure disaster recovery targets and automated failover policies, the manager must establish baseline metrics that explicitly bound maximum tolerable transactional data loss and the overall maximum timeframe the platform can remain offline before experiencing catastrophic regulatory penalties. Which of the following parameters must be established to satisfy these specific measurement requirements? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Recovery Point Objective (RPO) to establish the maximum acceptable age of unrecovered data resulting from an outage.; Maximum Tolerable Downtime (MTD) to define the total threshold of operational outage time the business process can sustain before suffering non-recoverable damage.

Cevap

The parameters that must be established are the Recovery Point Objective (RPO) to bound acceptable data loss timeframe, and the Maximum Tolerable Downtime (MTD) to establish the maximum allowable system outage duration.
The scenario requires defining metrics for two distinct thresholds: maximum tolerable transactional data loss and total allowable outage duration. Recovery Point Objective (RPO) specifies the maximum acceptable data loss measured in time, defining how recent restored backups must be. Maximum Tolerable Downtime (MTD) sets the absolute longest duration a business process can remain offline before encountering unacceptable consequences.

Adım Adım Çözüm

1
Analyze the BIA requirements for measuring data loss tolerance.
Identified Recovery Point Objective (RPO) as the metric determining the maximum acceptable temporal gap in transaction data loss.
RPO dictates backup frequency and replication architecture by defining how far back in time recovery must reach.
2
Analyze the BIA requirements for measuring overall allowable system outage limits.
Identified Maximum Tolerable Downtime (MTD) as the upper boundary for total business process outage duration.
MTD establishes the limit beyond which business operational disruption causes irreparable impact or non-compliance.
3
Evaluate remaining continuity metrics to eliminate non-matching targets.
Disqualified MTBF (a hardware reliability metric) and WRT (a post-recovery testing and process catch-up duration metric).
Neither MTBF nor WRT define maximum tolerable data loss or overall allowable outage duration limits.

Anahtar Kavram

Business Impact Analysis (BIA) metrics: RPO defines maximum acceptable data loss timeframe, whereas MTD sets the maximum overall tolerable outage duration.
Soru 1720Soru

A software development firm is deploying an automated continuous integration pipeline to release signed application updates to enterprise clients. To meet regulatory compliance, the pipeline must ensure that the authenticity of the code publisher can be independently verified by third parties and that the publishing organization cannot repudiate the origin of the software package. Which of the following cryptographic mechanisms best fulfills these requirements?

Cevabı ve açıklamayı göster

Cevap: Applying a digital signature using the organization's private key

Cevap

Applying a digital signature using the organization's private key best fulfills the requirement because asymmetric key pair signing uniquely identifies the origin and prevents non-repudiation.
A digital signature uses an asymmetric key pair where the creator signs data with their private key, and recipients verify it using the corresponding public key. Because only the owner possesses the private key, public verification guarantees both origin authenticity and non-repudiation.

Adım Adım Çözüm

1
Identify the required cryptographic properties from the scenario requirements.
The scenario specifically demands origin authenticity, third-party verifiability, and non-repudiation.
Regulatory compliance mandates that the origin of compiled code cannot be denied by the author and must be verifiable by end users.
2
Evaluate symmetric vs. asymmetric mechanisms against non-repudiation constraints.
Symmetric techniques (such as shared keys or symmetric encryption) allow any keyholder to generate valid codes/hashes, failing non-repudiation.
Non-repudiation requires a unique asymmetric private key owned strictly by the publishing entity.
3
Select the appropriate cryptographic mechanism.
Digital signatures generate a hash of the binary encrypted with the publisher's private key, which anyone can verify using the matching public key.
This guarantees integrity, origin authentication, and non-repudiation simultaneously.

Anahtar Kavram

Digital Signatures and Non-Repudiation
ÖncekiSayfa 86 / 112Sonraki
Tüm alıştırma soruları — CompTIA Security+ | Examkin